CVE-2026-23760: 
SmarterTools SmarterMail vulnerability analysis and mitigation

Overview

CVE-2026-23760 is an authentication bypass vulnerability in the password reset API of SmarterTools SmarterMail, allowing unauthenticated attackers to reset system administrator account passwords and achieve full administrative compromise. The vulnerability was discovered by watchTowr Labs researchers Piotr Bazydlo and Sina Kheirkhah on January 8, 2026, reported to the vendor, patched on January 15, 2026 (build 9511), and publicly disclosed on January 22, 2026. All SmarterMail versions prior to build 9511 (version 100.0.9511) are affected. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (watchTowr Labs, CISA KEV).

Technical details

The root cause is CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The vulnerable endpoint POST /api/v1/auth/force-reset-password is decorated with AllowAnonymous = true, permitting unauthenticated access. When the attacker-controlled IsSysAdmin field is set to true, the code path for resetting a system administrator password executes without verifying the OldPassword field or any reset token — despite the API accepting these fields. The regular user password reset path correctly validates the existing password, but the privileged administrator path does not. An attacker only needs to supply a valid administrator username (commonly admin or administrator) and a chosen new password in a JSON POST request to take over the account. Once admin access is obtained, SmarterMail's built-in Volume Mounts feature under Settings allows arbitrary OS command execution, escalating the auth bypass to full SYSTEM/root-level RCE (watchTowr Labs, Huntress).

Impact

Successful exploitation grants an unauthenticated attacker full administrative control over the SmarterMail instance, with high impact on confidentiality, integrity, and availability. Because SmarterMail system administrator privileges include the ability to execute OS commands via built-in management functionality, attackers effectively gain SYSTEM (Windows) or root (Linux) access on the underlying host. Real-world impacts have included ransomware deployment (WarLock and Medusa), data exfiltration, lateral movement across networks, and in at least one documented case, the vendor SmarterTools itself was breached through an unpatched instance of its own software (watchTowr Labs, Huntress, ReliaQuest).

Exploitability

This vulnerability is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on January 26, 2026, with a remediation due date of February 16, 2026. Exploitation was observed as early as January 17, 2026 — just two days after the patch was released — indicating attackers performed patch diffing to reconstruct the vulnerability. Multiple public PoC exploits are available, including on GitHub (MaxMnMl PoC) and a second PoC (hilwa24 PoC). The EPSS score is approximately 0.499 (49.9%), reflecting high exploitation probability. Threat actors Storm-2603 (deploying WarLock ransomware) and Storm-1175 (a China-linked group deploying Medusa ransomware, often within 24 hours of vulnerability disclosure) have been attributed to exploitation campaigns. Shadowserver identified over 6,000 internet-exposed SmarterMail servers likely vulnerable at the time of disclosure (CISA KEV, Huntress, Microsoft Security Blog, ReliaQuest).

Exploitation steps

  1. Reconnaissance: Identify internet-facing SmarterMail servers running versions prior to build 9511 using tools like Shodan or Censys, targeting the default HTTPS port (9998) or standard web ports.
  2. Username enumeration/guessing: Determine the system administrator username. In most deployments this defaults to admin or administrator; the API returns USER_NOT_FOUND for invalid usernames, enabling enumeration.
  3. Send auth bypass request: Submit an unauthenticated HTTP POST to /api/v1/auth/force-reset-password with the following JSON payload, setting IsSysAdmin to true:
POST /api/v1/auth/force-reset-password HTTP/1.1
Host: <target>:9998
Content-Type: application/json

{"IsSysAdmin":"true", "OldPassword":"anything", "Username":"admin", "NewPassword":"Attacker123!@#", "ConfirmPassword": "Attacker123!@#"}

A successful response returns "success":true with resultCode:200. 4. Authenticate as admin: POST to /api/v1/auth/authenticate-user with the newly set credentials to obtain a valid session token. 5. Achieve RCE via System Events: Use the admin session to POST to /api/v1/settings/sysadmin/event-hook to create a malicious system event containing an OS command payload. Trigger the event by adding a domain via /api/v1/settings/sysadmin/domain-put, causing the command to execute at SYSTEM/root level. 6. Cover tracks: Delete the malicious event hook and added domain via /api/v1/settings/sysadmin/event-hook-delete and /api/v1/settings/sysadmin/domain-delete/ to remove indicators of compromise. 7. Establish persistence/deploy payload: Drop ransomware, establish a reverse shell, or exfiltrate data from the now-compromised host (watchTowr Labs, Huntress).

Indicators of compromise

  • Network: HTTP POST requests to /api/v1/auth/force-reset-password from external/unexpected IP addresses; observed attacker IP ranges include 142.111.152[.]x and 155.2.215[.]x subnets; User-Agent string python-requests/2.32.4 associated with automated exploitation tooling.
  • Logs: SmarterMail access logs showing sequential POST requests to /api/v1/auth/force-reset-password, /api/v1/auth/authenticate-user, /api/v1/settings/sysadmin/event-hook, /api/v1/settings/sysadmin/domain-put, /api/v1/settings/sysadmin/domain-delete/, and /api/v1/settings/sysadmin/event-hook-delete in rapid succession; audit log entries for force-reset-password from unauthenticated or unexpected sources.
  • File System: Presence of C:\Program Files (x86)\SmarterTools\SmarterMail\Service\wwwroot\result.txt containing reconnaissance command output; unexpected files dropped in the SmarterMail web root or service directories.
  • Process: Unusual child processes spawned by the SmarterMail service process (e.g., cmd.exe, powershell.exe, bash) executing reconnaissance or payload delivery commands.
  • Behavioral: Unexpected new domains added and immediately deleted in SmarterMail; new system event hooks created and deleted in rapid succession; administrator account password changes with no corresponding legitimate admin activity (Huntress).

Mitigation and workarounds

The primary remediation is to upgrade SmarterMail to build 9511 or later, released January 15, 2026, which adds ValidatePassword verification to the system administrator password reset path. No vendor-provided workaround exists for unpatched systems; organizations unable to patch immediately should restrict network access to the SmarterMail API port (default 9998) and web interface to trusted IP ranges only, and monitor for suspicious POST requests to the /api/v1/auth/force-reset-password endpoint. CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by February 16, 2026. Given active ransomware exploitation, patching should be treated as an emergency priority (SmarterTools Release Notes, CISA KEV, watchTowr Labs).

Community reactions

The watchTowr Labs team (Piotr Bazydlo and Sina Kheirkhah) published a detailed technical write-up on January 22, 2026, noting that attackers appeared to have used decompilers to reverse-engineer the patch and reconstruct the vulnerability within days of its release — a technique they described as rare and alarming. Huntress independently observed and documented in-the-wild exploitation, publishing their own analysis the same day. The Shadowserver Foundation scanned the internet and reported over 6,000 exposed SmarterMail servers likely vulnerable, generating significant community concern on Reddit and security forums. The vulnerability attracted widespread media coverage from BleepingComputer, The Hacker News, SecurityWeek, and SC World, particularly after the WarLock ransomware group (Storm-2603) breached SmarterTools' own network using an unpatched instance of their own software — an irony widely noted in the security community. Microsoft's April 2026 threat intelligence blog further elevated awareness by linking Storm-1175 (a China-linked group) to exploitation of this CVE in Medusa ransomware operations, often deploying ransomware within 24 hours of gaining access (watchTowr Labs, Huntress, Microsoft Security Blog, ReliaQuest).

Additional resources


Source: This report was generated using AI

Related SmarterTools SmarterMail vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24423CRITICAL9.3
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
YesYesJan 23, 2026
CVE-2026-7807HIGH8.7
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesMay 08, 2026
CVE-2026-40514HIGH8.2
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesApr 27, 2026
CVE-2026-26930HIGH7.2
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesFeb 16, 2026
CVE-2026-25067MEDIUM6.9
  • SmarterTools SmarterMail logoSmarterTools SmarterMail
  • cpe:2.3:a:smartertools:smartermail
NoYesJan 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management